Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3085▲ 506 respecto a la semana anterior
Críticas / altas1460▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

5122 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.52%—Dataprobe Iboot-pdu4-n20 FirmwareDataprobe Iboot-pdu4sa-n15 FirmwareDataprobe Iboot-pdu4a-n15 FirmwareDataprobe Iboot-pdu4sa-n20 Firmware+1822/5/202317/6/2026
A proprietary protocol for iBoot devices is used for control and keepalive commands. The function compares the username and password; it also contains the configuration data for the user specified. If the user does not exist, then it sends a value for username and password, which allows successful authentication for a…
ModificadaCrítica (9.8)0.58%—Dataprobe Iboot-pdu4-n20 FirmwareDataprobe Iboot-pdu4sa-n15 FirmwareDataprobe Iboot-pdu4a-n15 FirmwareDataprobe Iboot-pdu4sa-n20 Firmware+1822/5/202317/6/2026
The affected product exposes multiple sensitive data fields of the affected product. An attacker can use the SNMP command to get device mac address and login as admin.
ModificadaCrítica (9.8)1.2%—Dataprobe Iboot-pdu4-n20 FirmwareDataprobe Iboot-pdu4sa-n15 FirmwareDataprobe Iboot-pdu4a-n15 FirmwareDataprobe Iboot-pdu4sa-n20 Firmware+1822/5/202317/6/2026
The affected product is vulnerable to a stack-based buffer overflow which could lead to a denial of service or remote code execution.
ModificadaMedia (6.5)0.17%—Dataprobe Iboot-pdu4-n20 FirmwareDataprobe Iboot-pdu4sa-n15 FirmwareDataprobe Iboot-pdu4a-n15 FirmwareDataprobe Iboot-pdu4sa-n20 Firmware+1822/5/202317/6/2026
The Dataprobe cloud usernames and passwords are stored in plain text in a specific file. Any user able to read this specific file from the device could compromise other devices connected to the user's cloud.
ModificadaMedia (6.5)0.52%—Johnsoncontrols Openblue Enterprise Manager Data Collector18/5/202317/6/2026
OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorized user under certain circumstances.
ModificadaAlta (7.5)1.1%💥 PoCJohnsoncontrols Openblue Enterprise Manager Data Collector18/5/202317/6/2026
Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain circumstances.
ModificadaCrítica (9.1)0.75%—Vmware Greenplum Database15/5/202317/6/2026
Greenplum Database (GPDB) is an open source data warehouse based on PostgreSQL. In versions prior to 6.22.3 Greenplum Database used an unsafe methods to extract tar files within GPPKGs. greenplum-db is vulnerable to path traversal leading to arbitrary file writes. An attacker can use this vulnerability to overwrite…
ModificadaAlta (7.8)0.21%—Intel AdvisorIntel CPU RuntimeIntel Distribution FOR PythonIntel Dpc++ Compatibility Tool+2510/5/202317/6/2026
Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.20%—Intel Data Center Manager10/5/202317/6/2026
Insecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (8.8)0.55%—Intel Data Center Manager10/5/202317/6/2026
Improper authentication in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via network access.
ModificadaAlta (7.8)0.17%—Intel Data Center Manager10/5/202317/6/2026
Insecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.17%—Intel Data Center Manager10/5/202317/6/2026
Uncontrolled search path in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (8.8)0.59%—Intel Data Center Manager10/5/202317/6/2026
Protection mechanism failure in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via network access.
ModificadaMedia (6.5)0.53%—Intel Data Center Manager10/5/202317/6/2026
Insufficiently protected credentials in the Intel(R) DCM software before version 5.0.1 may allow an authenticated user to potentially enable information disclosure via network access.
ModificadaAlta (7.8)0.20%—Intel Data Center Manager10/5/202317/6/2026
Exposure of data element to wrong session in the Intel DCM software before version 5.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.1)0.85%💥 ExploitMembership Database Project Membership Database8/5/202317/6/2026
The Membership Database WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaAlta (7.5)0.44%—IBM Qradar Data Synchronization6/5/202317/6/2026
IBM QRadar Data Synchronization App 1.0 through 3.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 217370.
ModificadaMedia (5.4)0.39%—Tms-outsource Wpdatatables3/5/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in TMS-Plugins wpDataTables plugin <= 2.1.49 versions.
ModificadaMedia (5.3)0.79%—Atlassian Confluence Data CenterAtlassian Confluence Server1/5/202317/6/2026
Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure vulnerability in the macro preview feature. This vulnerability was reported by Rojan Rijal of the Tinder…
ModificadaMedia (6.5)0.40%—IBM Watson Machine Learning ON Cloud PAK FOR Data27/4/202317/6/2026
IBM Watson Machine Learning on Cloud Pak for Data 4.0 and 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 253350.
ModificadaCrítica (9.8)1.1%—Gajshield Data Security Firewall Firmware27/4/202317/6/2026
This vulnerability exists in GajShield Data Security Firewall firmware versions prior to v4.28 (except v4.21) due to insecure default credentials which allows remote attacker to login as superuser by using default username/password via web-based management interface and/or exposed SSH port thereby enabling remote…
ModificadaAlta (7.2)0.87%—IBM Cloud PAK FOR Data26/4/202317/6/2026
IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 232034.
ModificadaMedia (6.5)1.3%—Solarwinds Database Performance Analyzer25/4/202317/6/2026
Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server.
ModificadaAlta (7.5)0.81%—Solarwinds Database Performance Analyzer25/4/202317/6/2026
No exception handling vulnerability which revealed sensitive or excessive information to users.
ModificadaAlta (7.8)0.24%—Datakit Crosscadware20/4/202317/6/2026
Datakit CrossCadWare_x64.dll contains an out-of-bounds write past the end of an allocated buffer while parsing a specially crafted SLDPRT file. This could allow an attacker to execute code in the context of the current process.